Files
chimera-gfx-Public/docs/retroarch/phase-1.0s-hbldr-shsrv-provenance.md
T
Chimera GFX release export fee37cd9b5
phase0-ci / build-and-audit (push) Failing after 1m41s
Publish Chimera GFX source
2026-09-03 02:53:36 +02:00

108 lines
5.0 KiB
Markdown

# Phase 1.0S: official shsrv/hbldr provenance
Status:
`BIGAPP_CONTEXT_SOURCE_PROVEN_DEPLOYED_IDENTITY_UNPROVEN_DEVICE_PATH_BLOCKED`
Date: 2026-07-22
This phase acquired and inspected only the official public
`ps5-payload-dev/shsrv` Git source. No downloaded code was built or executed.
No PS5 address was used, no connection or request was made, and no target
source, target artifact, transfer package, installation package, or device
client was created.
## Provenance boundary
The official repository is `https://github.com/ps5-payload-dev/shsrv`. During
the audit its `master`, latest release tag `v0.19`, and commit all resolved to
`6f320637d56d344a0e7797753099e33238bbf146`; the tree object is
`c26ce02b6c3ca4202993e039b3db7c28c353dee4`. The clean, detached historical
`v0.7` worktree resolves to commit
`74287f5db6b20320efd7892d7b29cf438fe7cb98` and tree
`7184968c702afe038551bf3228cc25f455388bb6`.
These source identities prove official implementations, not which shsrv
binary—if any—is installed or running on the target PS5. No locally supplied
shsrv/hbldr binary, package receipt, deployment log, or byte-exact device
identity was found. The deployed identity remains `UNPROVEN`.
## Why v0.7 and v0.19 are both relevant
The Phase-1.0Q LakeSnes source at commit
`a2db690123649c7ffbc68a663af31efb3a41bf3f` states that shsrv v0.7 or later is
required and launches the emulator with `hbldr`. Therefore v0.7 is the oldest
source-bound implementation relevant to that port documentation. Version
v0.19 is the latest official release inspected during Phase 1.0S.
The `hbldr` family began at commit
`4a70b50eecab853408f0a93a579b90428369fa09` as an experimental loader that
injects an ELF into a web application. The significant lineage is:
| Point | Commit/tag | Source-proven behavior |
|---|---|---|
| introduction | `4a70b50eecab853408f0a93a579b90428369fa09` | inject an ELF into a webapp process |
| LakeSnes minimum | `v0.7`, `74287f5...` | launch VideoPlayer BigApp `PPSA01659`, replace its process image |
| fake-game transition | `18e9a62aea801b5a1be4a692dba76bf5381e9fcb` | attach homebrew to a created fake game |
| first release containing transition | `v0.8` | fake-app/system-ex path present |
| current official release | `v0.19`, `6f32063...` | launch `FAKE00000`, replace its process image |
An official tag or source lineage is not deployed-use proof. The current
device may use no shsrv, a historical build, a current build, or a modified
binary.
## Exact source identities
### v0.19
| File | Size | SHA-256 |
|---|---:|---|
| `README.md` | 3,546 | `4855fa2adbe1fc0c7aa0174aa3275742d9b9aba3d818ae09cf2722a89b06cd34` |
| `shsrv.c` | 5,293 | `6ec71b4eb6c2bc1159f21568c1c9834f8aecac8d8881113bf09cf8981be19ee3` |
| `sh.c` | 13,278 | `3c4b7f76efdd157436ed4b353ee1b550bf3ff9df17c147b4762b767982fc8253` |
| `elfldr.c` | 17,911 | `4aa31f5a942681f8d88281b9713f087ced8963de842438cacad1088933f8e785` |
| `bundles/hbldr/main.c` | 1,520 | `6fa519888f79fe0458a983a517073c1eccc61239edfbe40d607f69b6b38a8af4` |
| `bundles/hbldr/hbldr.c` | 13,438 | `0096f86a00fdedcbc7509db47eb0f54dbc3e487d37e699f3de79048bac001be9` |
### v0.7
| File | Size | SHA-256 |
|---|---:|---|
| `README.md` | 3,248 | `3d16e46416dd07940fcde1190a6ab558348bc80263da615331dda0f3eb6183ed` |
| `shsrv.c` | 4,716 | `66197d08308180fe923aa8aedc91bd5025f08938156ae3092ea2c69d0ad0be57` |
| `sh.c` | 8,449 | `bf97bc6dd3f49345ad8da9a29b28a5d6bcde5e53a6f32c60a538d6e187c7e05a` |
| `elfldr.c` | 17,920 | `1ff6cfa1300a95e8be48e5f7adc1413e3384ba04ea266c167fcd441ef20197d1` |
| `bundles/hbldr/main.c` | 7,134 | `2081ece2f7d0a7e9b392660696c2a44802f64680365607e742b37dcf3223a55a` |
## PacBrew relationship
PacBrew commit `c2abcfcb60f569128abd0e8e70ad03a67bee5ea7` contains an shsrv recipe that
clones the official repository, uses `pkgver=git`, and declares
`sha256sums=('SKIP')`. It installs `shsrv.elf`, but does not pin the fetched
shsrv commit or prove which package was installed on the target. It is
`SOURCE_REPOSITORY_ASSOCIATION`, not byte-exact deployment provenance.
## Proven and unproven conclusions
`SOURCE_PROVEN`:
- the official hbldr family creates or launches a BigApp and replaces that
process with the requested ELF;
- v0.7 and v0.19 differ materially from raw elfldr's SceSpZeroConf process;
- both variants read the target ELF from a device path;
- both may terminate the currently running BigApp and perform kernel/ptrace
process mutations;
- v0.19 may remount and persistently populate `/system_ex/app/FAKE00000`.
`UNPROVEN`:
- which shsrv/hbldr binary is deployed;
- whether `FAKE00000` already exists on the target;
- whether the launcher works on the specific firmware-9.60 runtime;
- whether BigApp substitution provides the missing VideoOut permission;
- whether it would make the exact RetroArch first submit succeed;
- crash, cleanup, reboot, and visibility behavior on the target.
The source difference is a
`STRONG_SOURCE_CANDIDATE_NOT_PROVEN_ROOT_CAUSE`. It does not authorize using
hbldr, staging an ELF, connecting to shsrv, or creating a replacement launcher.